CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ACR Stealer: Two observed intrusion chains amid increased threat activity

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2732

As cited

Copy frozen at (site build).

threat intel

ACR Stealer: Two observed intrusion chains amid increased threat activity

Microsoft Defender Experts observed increased ACR Stealer activity from late April 2026 to mid-June 2026, identifying two distinct intrusion campaigns that use ClickFix social engineering to deliver information-stealing malware. Campaign 1 employs WebDAV-based payload delivery with Python loaders and blockchain-backed command-and-control, while Campaign 2 uses MSHTA and steganography for fileless execution. Both ultimately target browser credentials, authentication tokens, and sensitive enterprise documents.

Why it matters: Enterprise security teams need to detect and block ACR Stealer campaigns now; successful compromise exposes browser credentials and session tokens that enable account takeover, unauthorized cloud access, and further intrusion activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

ACR Stealer: Two observed intrusion chains amid increased threat activity

Microsoft Defender Experts observed increased ACR Stealer activity from late April 2026 to mid-June 2026, identifying two distinct intrusion campaigns that use ClickFix social engineering to deliver information-stealing malware. Campaign 1 employs WebDAV-based payload delivery with Python loaders and blockchain-backed command-and-control, while Campaign 2 uses MSHTA and steganography for fileless execution. Both ultimately target browser credentials, authentication tokens, and sensitive enterprise documents.

Why it matters: Enterprise security teams need to detect and block ACR Stealer campaigns now; successful compromise exposes browser credentials and session tokens that enable account takeover, unauthorized cloud access, and further intrusion activity.

VendorsMicrosoftGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary